A really cut-down list this week because I’ve got a 7-hour drive from Edinburgh to Oxford.
Interesting stats
30% of manufacturers experienced a cyber incident in the past 12 months, according to industry body MakeUK.
In brief
-
President Trump has signed an executive order to open the way for private sector participation in “limited cyber operations at the direction of the US government”. This is a pretty nuanced area that would be very easy to get wrong. Understandably then, opinions are divided.
-
Credentials from continuous integration pipelines were stolen from 2,5000 LiteLLM users. Organisations like Amazon, Cisco, Deloitte, and Vodafone were swept up when a compromised version of the software package was downloaded from the official Python Package Index. While some of the companies involved downplayed the incident as involving old credentials (from March), Kevin Beaumont, after checking the associated firm’s vulnerability disclosure policy, found that trying exposed credentials, “almost every one worked”.
-
A security researcher on their way home from Hacker Summer Camp created a fake in-flight Wi-Fi portal on a Delta Airlines flight from Las Vegas to Atlanta. While the safety of the flight was not affected, this is, in case you’re in any doubt, a really stupid thing to do. The antics may constitute a federal offence.
-
The UK Ministry of Defence found cameras on Royal Navy drones were sending heartbeat communications to a Chinese IP address. No indication that there was anything malicious, though it could be useful in determining numbers, and potentially broad locations, of the equipment.
-
Shipping giant Ceva Logistics has suffered a cyber attack affecting eight European warehouse locations. Attackers also stole personal data during the incident — names, addresses, and other shipping information — of customers receiving goods from retailers, banks, and more.
-
US Senators have introduced a $300 million bill to boost water cyber security. The Cyber Shield Act is in response to recent attacks against over 30 drinking and wastewater systems across 12 states, widely believed to be at the hands of Iran-linked groups, but which President Trump blamed on Minnesota.
-
Google Chrome has added support for device-bound session credentials (DBSCs) that mitigate session cookie theft and help prevent account takeovers.
-
Live facial recognition is coming to the London Underground. The system scans faces with a watchlist of people of interest to police, but has resulted in innocent people being mistaken and detained, often people of colour.
And finally
-
A person representing themselves in a US court hid prompt injections in filings to try and get AI models to side with him.
-
Software engineering PSA: Make sure you own any ‘no reply’ email addresses you use, and don’t use noreply.net.